GDPR Rights & Compliance

Your comprehensive guide to data protection rights under the General Data Protection Regulation.

Effective Date: September 5, 2025

The General Data Protection Regulation (GDPR) provides comprehensive data protection rights for individuals in the European Economic Area (EEA), United Kingdom, and Switzerland. RadPro AI is committed to protecting your privacy and ensuring full compliance with GDPR requirements, regardless of where you are located.

Important: This page outlines your rights under GDPR. For complete information about how we collect, use, and protect your data, please also review our Privacy Policy and Terms of Service. If you are a covered entity under HIPAA, additional protections apply as outlined in our Business Associate Agreement.

1. Data Controller Information

RadPro AI, a trade name of Radiology Pro AI Corp., an Ontario corporation, is the data controller responsible for processing your personal data under the General Data Protection Regulation (GDPR). We are located in Canada, and process data of users in the European Economic Area (EEA), United Kingdom, and Switzerland in accordance with GDPR requirements.

Our commitment to data protection extends across all jurisdictions where we operate. We maintain comprehensive data processing records, implement appropriate technical and organizational measures, and ensure transparency in all our data processing activities.

Contact Information: Company: Radiology Pro AI Corp. (RadPro AI) Location: Canada Email: admin@radpro.ai Website: https://radpro.ai

3. Your Rights Under GDPR

Under the GDPR, you have comprehensive rights regarding your personal data. We are committed to facilitating the exercise of these rights:

RIGHT TO ACCESS (Article 15) You have the right to obtain confirmation as to whether we process your personal data and, where that is the case, access to your personal data and information about the processing. This includes the right to receive a copy of your personal data undergoing processing. We will provide the first copy free of charge, though we may charge a reasonable fee for additional copies.

RIGHT TO RECTIFICATION (Article 16) You have the right to obtain the rectification of inaccurate personal data concerning you without undue delay. Taking into account the purposes of processing, you also have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

RIGHT TO ERASURE / "RIGHT TO BE FORGOTTEN" (Article 17) You have the right to obtain the erasure of your personal data without undue delay where one of the following grounds applies: - The personal data are no longer necessary for the purposes for which they were collected - You withdraw consent and there is no other legal ground for processing - You object to processing and there are no overriding legitimate grounds - The personal data have been unlawfully processed - Erasure is required for compliance with a legal obligation

Note: This right is subject to certain limitations, including where we must retain data for compliance with legal obligations (such as HIPAA's 6-year retention requirement for audit logs), for the establishment, exercise, or defense of legal claims, or for archiving purposes in the public interest.

RIGHT TO RESTRICT PROCESSING (Article 18) You have the right to obtain restriction of processing where one of the following applies: - You contest the accuracy of the personal data (restriction for a period enabling verification) - Processing is unlawful and you oppose erasure, requesting restriction instead - We no longer need the data but you require it for legal claims - You have objected to processing pending verification of whether legitimate grounds override yours

RIGHT TO DATA PORTABILITY (Article 20) You have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON, CSV) and have the right to transmit that data to another controller without hindrance from us, where: - Processing is based on consent or contract, and - Processing is carried out by automated means

We provide easy export functionality within your account settings to facilitate this right.

RIGHT TO OBJECT (Article 21) You have the right to object, on grounds relating to your particular situation, to processing of your personal data based on legitimate interests or performance of a task in the public interest. We will no longer process your data unless we demonstrate compelling legitimate grounds which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.

You have the absolute right to object to processing for direct marketing purposes at any time.

RIGHTS RELATED TO AUTOMATED DECISION-MAKING AND PROFILING (Article 22) You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. While RadPro AI uses artificial intelligence to assist with radiology reports, all AI-generated content must be reviewed and approved by a qualified healthcare professional before use in patient care. We do not make automated decisions that have legal or similarly significant effects without human intervention.

To exercise any of these rights, please contact us at admin@radpro.ai. We will respond to your request within one month, though this may be extended by two further months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receipt of the request, together with the reasons for the delay.

4. International Data Transfers

As RadPro AI operates globally and uses third-party services, your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including Canada and the United States. These countries may not provide the same level of data protection as your home country.

To ensure your data receives adequate protection when transferred internationally, we implement the following safeguards:

STANDARD CONTRACTUAL CLAUSES (SCCs) We use the European Commission's Standard Contractual Clauses (SCCs) for transfers of personal data to third countries. These are contractual commitments between companies transferring personal data, binding them to protect the privacy and security of your data. We use the SCCs adopted by the European Commission on June 4, 2021.

ADEQUACY DECISIONS Where possible, we transfer data to countries that have been deemed by the European Commission to provide an adequate level of data protection. We monitor adequacy decisions and adapt our transfer mechanisms accordingly.

SUPPLEMENTARY MEASURES In addition to SCCs, we implement supplementary technical, organizational, and contractual measures to ensure that data transferred outside the EEA receives a level of protection essentially equivalent to that guaranteed within the EEA. These measures include: - End-to-end encryption for data in transit (TLS 1.3) - Strong encryption at rest (AES-256) - Strict access controls and authentication mechanisms - Regular security assessments and audits - Data minimization and pseudonymization where appropriate - Contractual obligations on third-party processors

CANADIAN DATA PROTECTION As a Canadian company, we comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), which is recognized as providing substantial similarity to EU data protection requirements. Canada benefits from transitional adequacy decisions for commercial transfers.

THIRD-PARTY SERVICES Our primary third-party services that may involve international transfers include: - AI Model Hosting: OpenRouter (with SCCs and encryption) - Payment Processing: Stripe (Privacy Shield certified and SCC-compliant) - Cloud Infrastructure: AWS and Fly.io (GDPR-compliant with SCCs)

You have the right to obtain information about the safeguards we have implemented for international transfers by contacting admin@radpro.ai. We can provide copies of relevant adequacy decisions, SCCs, or information about other transfer mechanisms upon request.

5. Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee our data protection strategy and ensure compliance with GDPR requirements. Our DPO is responsible for:

- Monitoring compliance with GDPR and other data protection laws - Advising on data protection impact assessments - Cooperating with supervisory authorities - Acting as a contact point for supervisory authorities and data subjects - Providing guidance on data protection obligations - Managing data breach notifications and responses

You have the right to contact our Data Protection Officer directly regarding: - Questions about how we process your personal data - Concerns about your data protection rights - Complaints about our data processing activities - Requests to exercise your GDPR rights - Data protection impact assessments - Data breach notifications

Contact Our DPO: Email: admin@radpro.ai Subject Line: "ATTN: Data Protection Officer" Mail: Data Protection Officer RadPro AI Canada

When contacting our DPO, please include: - Your full name and contact information - Description of your inquiry or concern - Any relevant account information (if applicable) - Preferred method and language for response

Our DPO will respond to your inquiry within one month. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension and the reasons for delay.

The DPO operates independently and reports directly to the highest management level. Our DPO is not dismissed or penalized for performing their tasks and has the necessary resources and access to personal data and processing operations to fulfill their duties effectively.

6. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of your personal data infringes GDPR.

While we encourage you to contact us first at admin@radpro.ai to resolve any concerns, you have the right to lodge a complaint directly with a supervisory authority at any time.

EU/EEA SUPERVISORY AUTHORITIES Each EU Member State has its own supervisory authority. You can find the appropriate authority for your country at: https://edpb.europa.eu/about-edpb/board/members_en

Some prominent supervisory authorities include:

Ireland (for many tech companies): Data Protection Commission 21 Fitzwilliam Square South Dublin 2, D02 RD28 Ireland Phone: +353 57 868 4800 Email: info@dataprotection.ie Website: www.dataprotection.ie

Germany: The Federal Commissioner for Data Protection and Freedom of Information (BfDI) Graurheindorfer Str. 153 53117 Bonn Germany Phone: +49 228 997799-0 Email: poststelle@bfdi.bund.de Website: www.bfdi.bund.de

France: Commission Nationale de l'Informatique et des Libertés (CNIL) 3 Place de Fontenoy TSA 80715 75334 Paris Cedex 07 France Phone: +33 1 53 73 22 22 Website: www.cnil.fr

United Kingdom: Information Commissioner's Office (ICO) Wycliffe House, Water Lane Wilmslow, Cheshire SK9 5AF United Kingdom Phone: +44 303 123 1113 Website: www.ico.org.uk

COMPLAINT PROCESS When lodging a complaint with a supervisory authority, you should provide: - Your contact information - Description of the alleged infringement - Details about the data controller - Any evidence supporting your complaint - Any correspondence with us regarding the issue

The supervisory authority will investigate your complaint and may: - Request information from us - Conduct audits or inspections - Issue warnings or reprimands - Impose administrative fines - Order us to comply with your data subject rights - Impose temporary or permanent processing bans

CANADIAN PRIVACY COMMISSIONER As a Canadian company, you may also lodge a complaint with: Office of the Privacy Commissioner of Canada 30 Victoria Street Gatineau, Quebec K1A 1H3 Canada Phone: 1-800-282-1376 Email: info@priv.gc.ca Website: www.priv.gc.ca

Please note that lodging a complaint with a supervisory authority does not affect your ability to seek judicial remedy or other forms of redress.

7. Data Retention Periods

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.

ACCOUNT DATA Active Accounts: Your account information and preferences are retained for the duration of your active account. Inactive Accounts: If you do not log in for 24 months, we may contact you to confirm whether you wish to maintain your account. Deletion Requests: Upon request, we will delete your account and associated personal data within 30 days, subject to legal retention requirements outlined below.

RADIOLOGY REPORT DATA Processed Reports: Radiology reports you choose to save are retained in your account until you delete them or close your account. Temporary Processing Data: Reports processed through our AI but not saved are automatically deleted within 24 hours of processing. PHI-Scrubbed Data: Anonymized report data (with all PHI removed) may be retained for service improvement purposes.

HIPAA COMPLIANCE - 6-YEAR RETENTION To comply with HIPAA requirements, certain records are retained for a minimum of 6 years from the date of creation or last effective date: - Audit logs of PHI access and processing - Security incident records - Compliance documentation - Business Associate Agreement records - Access control records - System activity logs involving PHI

These records are maintained in secure, access-controlled systems and are automatically deleted after the required retention period unless legal proceedings or investigations require extended retention.

PAYMENT AND BILLING DATA Transaction Records: Payment transactions are retained for 7 years to comply with tax laws and accounting requirements. Credit Card Information: We do not store complete credit card numbers. Payment processing is handled by Stripe, which maintains PCI DSS compliance. Invoices: Billing records and invoices are retained for 7 years for accounting and tax purposes.

COMMUNICATIONS Email Correspondence: Support emails and communications are retained for 3 years to maintain service quality and resolve disputes. Marketing Communications: Records of consent and unsubscribe requests are retained indefinitely to ensure compliance with your preferences.

LEGAL AND COMPLIANCE Legal Holds: Data subject to legal proceedings, investigations, or regulatory requests is retained until the matter is resolved. Backup Systems: Data in backup systems may persist for up to 90 days after deletion from production systems but is not accessible for normal operations.

ANALYTICS AND AGGREGATED DATA Anonymized Usage Analytics: Aggregated, anonymized data with no personal identifiers may be retained indefinitely for statistical analysis and service improvement. Performance Metrics: De-identified performance data is retained to improve AI models and service quality.

YOUR RIGHTS REGARDING RETENTION Despite the retention periods outlined above, you have the right to: - Request deletion of your data at any time (subject to legal retention requirements) - Object to processing for legitimate interests - Request restriction of processing during disputes about accuracy or legitimate grounds - Obtain information about specific retention periods for your data

To exercise these rights or request information about retention of your specific data, contact admin@radpro.ai.

AUTOMATED DELETION We implement automated deletion processes to ensure data is not retained longer than necessary: - Daily cleanup of temporary processing files - Monthly review of inactive sessions - Annual audit of retention compliance - Automated deletion of data past retention periods

Our retention policies are regularly reviewed and updated to ensure compliance with evolving legal requirements and best practices in data protection.

Quick Reference: How to Exercise Your Rights

Simple steps to exercise your GDPR rights

Access Your Data

Request a complete copy of your personal data within 30 days.

Email: admin@radpro.ai with subject "Data Access Request"

Correct Your Data

Update inaccurate information in your account or records.

Use account settings or email admin@radpro.ai

Delete Your Data

Request deletion of your account and personal data.

Account settings or email with subject "Deletion Request"

Export Your Data

Download your data in standard formats (JSON, CSV).

Use account export feature or request via email

Contact Our Data Protection Officer

For any questions about your GDPR rights or our data processing activities:

Data Protection Officer

Email: admin@radpro.ai

Subject Line: "ATTN: Data Protection Officer"

Mail:
Data Protection Officer
RadPro AI
Canada

Right to Lodge a Complaint

While we strive to address all concerns directly, you have the right to lodge a complaint with a supervisory authority in your jurisdiction. You can find your local authority at:

European Data Protection Board - Supervisory Authorities

Canadian users may also contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca

This GDPR Rights page is part of our commitment to transparency and data protection. For complete information about our data practices, please review our Privacy Policy and Terms of Service. We regularly update our policies to reflect changes in law and best practices.

Last updated: September 25, 2026